All Apps and Add-ons

After installing the Cisco Networks App and Add-on for Splunk Enterprise 2.3.0 on Splunk 6.2, why do dashboards now show "he lookup table 'cisco_ios_facility_categories' does not exist."

molinarf
Communicator

Lookup table error: The lookup table 'cisco_ios_facility_categories' does not exist. It is referenced by configuration 'source::udp:514|host::10.32.7.7|cisco:ios'.

I upgraded to TA-Cisco_ios 2.3 and ran into this issue. With the errors that were occurring in lookup tables, I removed the app completely and then reinstalled. Both the TA and Cisco Network Apps are at version 2.3. With the IP address, it could be the switch is sending information that Splunk doesn't know how to deal with. Any ideas? I am in the process of trying to determine what the entry in the eventtypes,conf will be and what the switch is trying to send. If you can provide some insight, it would be appreciated.

0 Karma
1 Solution

mikaelbje
Motivator

Did you do a complete reinstall of TA-cisco_ios on your indexers too? Make sure the versions match on indexer and search head. As you said a complete reinstall (delete directories) and re-add apps is necessary. This has solved the exact issue you are facing for others, including myself at various customer sites.

View solution in original post

0 Karma

molinarf
Communicator

Thank you for your assistance. It is not intuitive that we should do a complete re-install and something to remember in the future. When I removed the directories for the TA-cisco_ios and the Cisco network apps and then re-installed, the issue went away.

0 Karma

mikaelbje
Motivator

Sorry about that. Some files were moved from the app to the add-on and vice versa in an previous version and that's why this happens. There's no local/default concept for the lookup directory so any old lookups are retained even when you upgrade apps.

0 Karma

mikaelbje
Motivator

Did you do a complete reinstall of TA-cisco_ios on your indexers too? Make sure the versions match on indexer and search head. As you said a complete reinstall (delete directories) and re-add apps is necessary. This has solved the exact issue you are facing for others, including myself at various customer sites.

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...